Enforce dependency edge ownership across Braid - #92
Merged
Merged
Conversation
Closed
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependency authority belongs to direct authored edges, not the accidental transitive lockfile closure.
The old gate warned about roughly 100 transitive packages from one build script while being unable to name the workspace crate that created an edge. Enforcement was stood down, direct serde/serde_json/proptest/tempfile bypasses remained, and copied foreign workspace crates were indistinguishable from local authority.
This change makes
cargo metadata --no-depsthe source of direct-edge truth. Every approval now records its owning crate, semantic capability, exact manifest requirement, source class, allowed consumers, and allowed dependency kinds. The register is enforced. Unowned edges, wrong consumers, requirement/source/kind drift, copied foreign workspace members, and stale approvals refuse.The crate graph now follows the same contract:
lgwks_std; the no-std capability token retains one explicit boundary.braid-test-supportcrate.braid-integrateno longer declares serde, serde_json, or tempfile directly.lgwks-gate check .command is lane 4 locally and the first GitHub build gate.I rejected expanding
APPROVED.tomlinto a transitive whitelist. Cargo.lock remains exact byte provenance; it does not grant package-level authority.Real paths:
Regression coverage includes inactive optional/dev metadata edges, unregistered path copies, foreign Braid workspace copies, registry-to-Git drift, wrong consumers, and approvals that outlive their owner edge.
Local CI is green across all 28 lanes for exact SHA
2cd10d953093502bb91532a910b423d2c97b951f; receipt:/Users/srinji/wwfd/state/local-ci-receipt.json.Closes #91.
Still not done: issue #75 must publish the crate family before issue #76 can migrate external consumers without path or floating-Git fallbacks. The constellation census remains the ordered migration ledger for those follow-up PRs.